AI is finding bugs faster than humans can fix them: How enterprise security teams must adapt
It's far easier to find security holes than to fix them, and leaving it to AI can introduce 9 times as many new vulnerabilities as developers do.
The rapid pace of AI-assisted vulnerability discovery is outstripping the ability of security teams to keep up with the overwhelming influx of bug reports. While AI tools like Google's agents have significantly accelerated the process of finding security holes, the reality is that most companies lack the resources to fix such a large volume of issues.
Even tech giants like Apple have had to impose limits on the number of vulnerabilities that security researchers can submit. This mismatch between discovery and resolution is creating an ever-growing burden on developers, security teams, and companies attempting to differentiate exploitable issues from noise generated by AI. The problem extends beyond developers, as system administrators, CISOs, and end users also struggle to keep up with the constant stream of patches.
The traditional approach of patching high-value bugs immediately has become obsolete, as the sheer volume of updates has surpassed what security teams can manage. Microsoft's July 2026 Patch Tuesday alone shipped 570 patches, including three zero-days, setting a record that is likely to be broken before the year ends. This trend is not restricted to open-source software; Microsoft's own systems have been under pressure due to the increased volume of security updates.
The challenge is further compounded by the fact that not all vulnerabilities are equally threatening. A small percentage are actively exploited, while many others are part of the background hum of fixes. Security teams are now tasked with triaging issues where the sheer volume itself poses a risk multiplier. For instance, Adobe's recent Acrobat Chrome extension security flaw, HermeticReader, demonstrated how AI can be used to link together multiple vulnerabilities, leading to a zero-click exploit that extracted sensitive WhatsApp Web data.
This incident highlights the growing threat of AI-generated exploits and the need for security teams to adapt their strategies to manage the rapidly evolving landscape.
Written by urgent.news from ZDNet's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.